Privacy · Independent guidance

Privacy: local tools and minimal analytics

Configuration, schema, diagnostic, audit, cost, and skill-builder inputs are processed in your browser. The website has no application endpoint for those inputs. Do not paste a real secret anyway: screen capture, browser extensions, shared devices, clipboard history, and your own downloads remain outside this site’s control.

Updated 2026-08-24
01

What the tools do locally

  • Parse supported JSON/JSON5-like input and generate deterministic findings.
  • Detect common token, key, authorization, private-key, webhook, path, email, phone, IP, and identifier patterns.
  • Run a second redaction pass before copy or download.
  • Clear imported text when you reset the tool or leave the page.
  • Keep shareable state limited to public enumerated choices and numeric cost assumptions.
02

Analytics boundary

If analytics is enabled, it is limited to page views and coarse events such as tool name plus success/failure category. Pasted text, output, commands, field values, model selections, URLs containing state, detected secrets, or fine-grained diagnostic signatures are excluded.

03

Your safest workflow

  1. 1

    Use placeholders first

    Replace keys, tokens, account IDs, domains, hostnames, paths, and phone numbers before paste.

  2. 2

    Prefer the smallest excerpt

    A focused structured report exposes less than a full log archive.

  3. 3

    Rotate after exposure

    If a real secret appeared in a paste, screenshot, issue, or shared clipboard, treat it as compromised.

Primary sources

Verify against the owner.

This page states project policy rather than version-sensitive OpenClaw behavior.